Zum Inhalt springen

Wordpress Updates & Release Notes

6 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge Wordpress, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Wordpress von Automattic

WordPress 7.1.3 – Wartungs- und Sicherheitsupdate

WordPress 7.1.3 enthält 7 Sicherheitskorrekturen und 4 Fehlerbehebungen, darunter Korrekturen für Stored XSS auf der Kommentarseite, SQL-Injection im WXR-Export und die Offenlegung von Kommentaren privater Beiträge, und sollte sofort installiert werden.

This security and maintenance release features 7 security fixes and 4 bug fixes.

Because this is a security release, it is recommended that you update your sites immediately.

You can download WordPress 7.1.3 from WordPress.org, or visit your WordPress Dashboard, click “Updates”, and then click “Update Now”. If you have sites that support automatic background updates, the update process will begin automatically.

Security updates included in this release

The security team would like to thank the following people and organizations for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:

  • A stored XSS on the Comments administration page, exploitable via pending comments, reported by Thomas Chauchefoin at Trail of Bits
  • A DoS issue in the WP_Http::make_absolute_url() method, reported by Anthropic
  • A second-Order SQL injection in WordPress WXR export, reported by Anthropic
  • A weakness allowing Author role users to sticky posts, reported by Anthropic
  • Unauthenticated disclosure of comments on private & unpublished posts, reported by Ananda Dhakal from Patchstack …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Wordpress von Automattic

WordPress 7.1.2 – Sicherheitsupdate gegen kritische Lücke

WordPress 7.1.2 behebt eine kritische Sicherheitslücke, durch die ein nicht authentifizierter Angreifer unter bestimmten Bedingungen eine lokale PHP-Datei einbinden und so Remote Code Execution auslösen konnte, weshalb ein sofortiges Update empfohlen wird.

This security release features a fix for a critical severity security vulnerability.

Because this is a security release, it is recommended that you update your sites immediately.

You can download WordPress 7.1.2 from WordPress.org, or visit your WordPress Dashboard, click “Updates”, and then click “Update Now”. If you have sites that support automatic background updates, the update process will begin automatically.

Security update included in this release

The security team would like to thank Robert Ressl for responsibly disclosing that an unauthenticated attacker can, under certain conditions, make page template resolution include a chosen readable local PHP file outside the active theme directories. If relevant pre-conditions for both the server environment and the active theme are met, this can lead to remote code execution (RCE).

Thank you to these WordPress contributors

This release was led by John Blackbourn. WordPress 7.1.2 would not have been possible without the contributions of the following people: …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Wordpress von Automattic

WordPress 7.1.1 – Wartungs- und Sicherheitsupdate

WordPress 7.1.1 bringt 17 Fehlerbehebungen im Core, 19 im Block Editor und 11 Sicherheitskorrekturen, darunter eine für Stored XSS in wpautop(), und sollte sofort installiert werden.

This security and maintenance release features 17 bug fixes on Core, 19 bug fixes for the Block Editor, and 11 security fixes.

Because this is a security release, it is recommended that you update your sites immediately.

You can download WordPress 7.1.1 from WordPress.org, or visit your WordPress Dashboard, click “Updates”, and then click “Update Now”. If you have sites that support automatic background updates, the update process will begin automatically.

WordPress 7.1.1 is a short-cycle release. The next major release will be version 7.2 and is currently planned for December.

For more information, please visit the WordPress 7.1.1 HelpHub site.

Security updates included in this release

The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.). …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Wordpress von Automattic

WordPress 7.1 „Mary Lou“

WordPress 7.1 mit dem Codenamen „Mary Lou“ ist erschienen und ehrt die Jazzpianistin Mary Lou Williams.

Each WordPress release celebrates an artist who has made an indelible mark on the world of music. WordPress 7.1, code-named “Mary Lou,” honors pioneering jazz pianist, arranger, and composer Mary Lou Williams.

A child prodigy who began playing publicly at six, her influence and work cut across nearly every major era of jazz, moving through swing, bebop, and sacred jazz. Through all of it, she kept reinventing her own sound. In the 1940s, she turned her Harlem apartment into a nightly workshop where Thelonious Monk, Dizzy Gillespie, and Bud Powell came to trade ideas and shape bebop itself. That combination of reinvention and collaboration inspired WordPress 7.1.

Let the range of Mary Lou’s music carry you through everything 7.1 offers.

Welcome to WordPress 7.1! …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Wordpress von Automattic

Neue WordPress Browser Extension für Chrome und Safari

Die offizielle, quelloffene WordPress Browser Extension für Chrome, Chromium-Browser und Safari auf macOS blendet die Admin-Leiste aus, behält deren wichtigste Shortcuts in der Browser-Symbolleiste und bietet schnellen Zugriff auf alle eigenen WordPress-Sites sowie Werkzeuge für Entwickler und Content-Ersteller.

The official WordPress Browser Extension is now available for Google Chrome and Chromium-based browsers in the Chrome Web Store and for Safari on macOS in the Mac App Store. This new open source extension lets logged-in site users easily hide the admin bar while keeping its most helpful shortcuts in the browser toolbar, provides quick access to all of your WordPress sites, and adds helpful tools for developers and content creators.

Decorative screenshot of the new WordPress Browser Extension

By default, the admin bar sits at the top of every page you view while signed in to WordPress, keeping the dashboard, the editor, and your profile within reach. That convenience carries a cost: the bar occupies the viewport, so the page on screen is never quite the page a visitor sees. On sites doing more interesting things with the viewport, such as sticky headers or scroll-driven effects, it can introduce artifacts that send you hunting for a bug that is not there. Further, the admin bar can sometimes grow unwieldy as plugins add their own features and shortcuts to it. Switching it off in your profile settings trades one problem for another, because the shortcuts leave with it. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Wordpress von Automattic

WordPress 7.0.4 – Sicherheitsupdate

WordPress 7.0.4 behebt eine Sicherheitslücke, bei der authentifizierte Nutzer ab Author-Rolle über einen schädlichen Datei-Upload auf Sites mit Imagick und Ghostscript Remote Code Execution auslösen konnten.

WordPress 7.0.4 is now available

WordPress 7.0.4 is now available which features a security fix. Because this is a security release, it is recommended that you update your sites immediately.

You can update to WordPress 7.0.4 by downloading it from WordPress.org, or visiting your site’s Dashboard → Updates and clicking Update Now. Sites that support automatic background updates will begin updating shortly.

For more information, please visit the WordPress 7.0.4 HelpHub site.

Security update included in this release

The security team would like to thank the team at pwn.ai for responsibly reporting the following vulnerability and allowing it to be fixed in this release:

  • Authenticated Author+ remote code execution via malicious file upload on sites that use Imagick and Ghostscript.

Backports

As a courtesy, these fixes are being backported through to the 4.7 branch and the 7.1 RC3 release that’s due later today. As a reminder, only the most recent version of WordPress is actively supported. The backports are in progress and will ship as they become ready.

CVE and GHSA references

Further details can be found in the advisory: CVE-2026-65640 / GHSA-8vr3-7mxf-gx8w.

Thank you to these WordPress contributors …

Originalquelle(öffnet in neuem Tab)Problem melden